Description
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2011-2231 Vulnerability (CVE-2011-2231)
MySQL CVE-2017-3456 Vulnerability (CVE-2017-3456)
WebLogic CVE-2024-20927 Vulnerability (CVE-2024-20927)
PostgreSQL Improper Authentication Vulnerability (CVE-2017-7546)
SharePoint Improper Input Validation Vulnerability (CVE-2019-0594)